安全研究

安全漏洞
Apache Tomcat DefaultServlet文件泄露漏洞

发布日期:2002-09-24
更新日期:2008-09-05

受影响系统:
Apache Group Tomcat 4.1.10
Apache Group Tomcat 4.0.4
描述:
BUGTRAQ  ID: 5786
CVE(CAN) ID: CVE-2002-1148,CVE-2002-1148

Apache Tomcat是一个流行的开源JSP应用服务器程序。

Tomcat 4.0.4、4.1.10的默认小服务程序在接到远程攻击者发送的直接请求时,存在错误,可使远程攻击者读取服务器文件的源代码。

<*来源:Rossen Raykov (Rossen.Raykov_at_CognicaseUSA.com)
  *>

测试方法:

警 告

以下程序(方法)可能带有攻击性,仅供安全研究与教学之用。使用者风险自负!

http://target/admin/servlet/org.apache.catalina.servlets.DefaultServlet/target.jsp

建议:
厂商补丁:

Apache Group
------------
目前厂商已经发布了升级补丁以修复这个安全问题,请到厂商的主页下载:

http://jakarta.apache.org/tomcat/index.html




Sun Solaris 9
Sun 113146-11
http://sunsolve.sun.com/search/document.do?assetkey=urn:cds:docid:1-21 -113146-11-1

Sun 114016-02
http://sunsolve.sun.com/search/document.do?assetkey=urn:cds:docid:1-21 -114016-02-1


Sun Solaris 9_x86
Sun 114017-02
http://sunsolve.sun.com/search/document.do?assetkey=urn:cds:docid:1-21 -114017-02-1

Sun 114145-10
http://sunsolve.sun.com/search/document.do?assetkey=urn:cds:docid:1-21 -114145-10-1


Apache Software Foundation Tomcat 3.0
Apache Software Foundation Jakarta Tomcat 4.0.5
http://jakarta.apache.org/builds/jakarta-tomcat-4.0/release/v4.0.5/


Apache Software Foundation Tomcat 3.1
Apache Software Foundation Jakarta Tomcat 4.0.5
http://jakarta.apache.org/builds/jakarta-tomcat-4.0/release/v4.0.5/


Apache Software Foundation Tomcat 3.1.1
Apache Software Foundation Jakarta Tomcat 4.0.5
http://jakarta.apache.org/builds/jakarta-tomcat-4.0/release/v4.0.5/


Apache Software Foundation Tomcat 3.2
Apache Software Foundation Jakarta Tomcat 4.0.5
http://jakarta.apache.org/builds/jakarta-tomcat-4.0/release/v4.0.5/


Apache Software Foundation Tomcat 3.2.1
Apache Software Foundation Jakarta Tomcat 4.0.5
http://jakarta.apache.org/builds/jakarta-tomcat-4.0/release/v4.0.5/


Apache Software Foundation Tomcat 3.2.2 beta2
Apache Software Foundation Jakarta Tomcat 4.0.5
http://jakarta.apache.org/builds/jakarta-tomcat-4.0/release/v4.0.5/


Apache Software Foundation Tomcat 3.2.3
Apache Software Foundation Jakarta Tomcat 4.0.5
http://jakarta.apache.org/builds/jakarta-tomcat-4.0/release/v4.0.5/


Apache Software Foundation Tomcat 3.2.4
Apache Software Foundation Jakarta Tomcat 4.0.5
http://jakarta.apache.org/builds/jakarta-tomcat-4.0/release/v4.0.5/


Apache Software Foundation Tomcat 3.3
Apache Software Foundation Jakarta Tomcat 4.0.5
http://jakarta.apache.org/builds/jakarta-tomcat-4.0/release/v4.0.5/


Apache Software Foundation Tomcat 3.3.1
Apache Software Foundation Jakarta Tomcat 4.0.5
http://jakarta.apache.org/builds/jakarta-tomcat-4.0/release/v4.0.5/


Apache Software Foundation Tomcat 4.0
Apache Software Foundation Jakarta Tomcat 4.0.5
http://jakarta.apache.org/builds/jakarta-tomcat-4.0/release/v4.0.5/


Apache Software Foundation Tomcat 4.0.1
Apache Software Foundation Jakarta Tomcat 4.0.5
http://jakarta.apache.org/builds/jakarta-tomcat-4.0/release/v4.0.5/


Apache Software Foundation Tomcat 4.0.2
Apache Software Foundation Jakarta Tomcat 4.0.5
http://jakarta.apache.org/builds/jakarta-tomcat-4.0/release/v4.0.5/


Apache Software Foundation Tomcat 4.0.3
Apache Software Foundation Jakarta Tomcat 4.0.5
http://jakarta.apache.org/builds/jakarta-tomcat-4.0/release/v4.0.5/

Debian libtomcat4-java_4.0.3-3woody1_all.deb
http://security.debian.org/pool/updates/contrib/t/tomcat4/libtomcat4-j ava_4.0.3-3woody1_all.deb

Debian tomcat4-webapps_4.0.3-3woody1_all.deb
http://security.debian.org/pool/updates/contrib/t/tomcat4/tomcat4-weba pps_4.0.3-3woody1_all.deb

Debian tomcat4_4.0.3-3woody1_all.deb
http://security.debian.org/pool/updates/contrib/t/tomcat4/tomcat4_4.0. 3-3woody1_all.deb


Apache Software Foundation Tomcat 4.0.4
Apache Software Foundation Jakarta Tomcat 4.0.5
http://jakarta.apache.org/builds/jakarta-tomcat-4.0/release/v4.0.5/


Apache Software Foundation Tomcat 4.1
Apache Software Foundation Jakarta Tomcat 4.1.12
http://jakarta.apache.org/builds/jakarta-tomcat-4.0/release/v4.1.12/


Apache Software Foundation Tomcat 4.1.10
Apache Software Foundation Jakarta Tomcat 4.1.12
http://jakarta.apache.org/builds/jakarta-tomcat-4.0/release/v4.1.12/


Apache Software Foundation Tomcat 4.1.3 beta
Apache Software Foundation Jakarta Tomcat 4.1.12
http://jakarta.apache.org/builds/jakarta-tomcat-4.0/release/v4.1.12/


Apache Software Foundation Tomcat 4.1.9 beta
Apache Software Foundation Jakarta Tomcat 4.1.12
http://jakarta.apache.org/builds/jakarta-tomcat-4.0/release/v4.1.12/

浏览次数:2262
严重程度:0(网友投票)
本安全漏洞由绿盟科技翻译整理,版权所有,未经许可,不得转载
绿盟科技给您安全的保障